Data Processing Agreement (DPA)

Last updated: August 28, 2026

1. Purpose and Scope

This Data Processing Agreement ("DPA") supplements the Terms of Service between you and Fluxon LLC ("Processor") and applies to the processing of personal data under applicable data protection laws, including GDPR, CCPA, UK GDPR, Swiss FADP, and others.

This DPA applies to all personal data processed by Fluxon LLC on your behalf ("Controller") through the GateLLM software.

GateLLM is an enterprise large language model (LLM) gateway. Unlike traditional record-keeping SaaS, GateLLM's core function is to read free-text prompts input by the Controller and forward them to downstream model provider APIs configured by the Controller. This DPA is specifically designed for this data-flow characteristic and discloses the data-use practices of 100+ downstream model providers by category (see Section 8).

2. Definitions

"Personal Data", "Processing", "Controller", "Processor", and "Data Subject" have the meanings given to them in applicable data protection laws.

"Applicable Data Protection Laws" means all laws applicable to the processing of personal data, including but not limited to the EU General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), the California Consumer Privacy Act (CCPA), and the Swiss Federal Act on Data Protection (FADP).

"Sub-processor" means any third party engaged by the Processor to process personal data on behalf of the Controller.

"Downstream Model Provider" means any large language model service provider that the Controller configures in GateLLM via BYOK (bring-your-own-key), such as Anthropic, OpenAI, Google, Zhipu, Alibaba Cloud, DeepSeek, and 100+ others. The legal status of downstream model providers is addressed in Section 8.2.

"Prompt" means any free-text content input to GateLLM by the Controller or its authorized users, including text that may contain personal data.

3. Roles of Controller and Processor

For personal data processed through GateLLM:

  • You (the Customer) are the Controller, determining the purposes and means of processing, including which downstream model providers to enable and in which scenarios prompts containing personal data are processed.
  • Fluxon LLC is the Processor, processing personal data on your instructions. GateLLM is deployed in a fully self-hosted manner within infrastructure (VPC / on-premises data center) owned or controlled by the Controller. The Processor does not host, relay, or store the Controller's prompts or completions.
  • You are responsible for ensuring you have the right to process the relevant personal data and have obtained all necessary consents and authorizations, in particular the authorization to forward personal data to your selected downstream model providers.

4. Scope and Purpose of Processing

The Processor will process personal data on behalf of the Controller for the following purposes:

  • Providing and maintaining the GateLLM software itself (license issuance and validation)
  • Managing accounts and subscriptions (contact information, license status)
  • Processing payments (handled by Stripe as a sub-processor)
  • Providing technical support (content of support requests proactively submitted by the Controller)
  • Complying with legal obligations

Nature of processing: GateLLM's runtime processing of prompts is automated in-memory forwarding and retrieval, not persisted in the Processor's systems after completion (see Section 9 for details). Account- and license-level personal data involves storage and retrieval.

Important: The prompt / completion data flow at GateLLM runtime occurs entirely within the Controller's infrastructure. The Processor's (Fluxon LLC's) runtime systems do not receive, store, or relay this data. References in this DPA to "the Processor processing prompt-related personal data" describe the data flow that the GateLLM software performs on the Controller's behalf within the Controller's infrastructure — not the Processor, as a separate entity, coming into contact with that data.

5. Types of Personal Data Processed

The types of personal data that may be processed fall into two categories:

  • Account and license data (held in Processor systems): contact information (name, email address, company name); account information (login credentials, preference settings); payment information (billing information processed by Stripe); technical data (IP addresses, browser information, access logs); usage data (license usage and performance metrics).
  • Prompt-related data (flows through the GateLLM software within the Controller's infrastructure only; not held by the Processor): prompt content input by the Controller or its users; completion content returned by model providers. This data may contain personal data that the Controller chooses to include in prompts. The GateLLM software does not persist such data outside the gateway process after forwarding.

6. Categories of Data Subjects

The categories of data subjects covered by this DPA include:

  • The Controller's employees and representatives (authorized users of GateLLM)
  • The Controller's customers and end users (whose data may appear in prompts)
  • Other individuals interacting with the Controller (whose information the Controller may input as a prompt in the course of business processing)

7. Processor's Obligations (GDPR Art 28(3) Mapping)

The Processor assumes the following obligations under Article 28(3) of the GDPR:

  • Process personal data only on the Controller's documented instructions, including forwarding prompts to the downstream model providers designated by the Controller, unless required to do otherwise by law (GDPR Art 28(3)(a))
  • Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (GDPR Art 28(3)(b))
  • Implement appropriate technical and organizational measures to protect personal data (GDPR Art 28(3)(c); specific measures in Section 9)
  • Comply with the requirements regarding sub-processors, including prior specific or general written authorization and notification (GDPR Art 28(3)(d); see Section 8)
  • Assist the Controller in fulfilling its obligations to respond to data subject rights requests (GDPR Art 28(3)(e); see Section 12)
  • Assist the Controller in fulfilling its obligations under Articles 32 to 36 of the GDPR (security, breach notification, DPIA, prior consultation) (GDPR Art 28(3)(f))
  • Delete or return personal data at the end of the service or at the Controller's request (GDPR Art 28(3)(g); see Section 14)
  • Make available all information necessary to demonstrate compliance with this DPA and allow for audits (GDPR Art 28(3)(h); see Section 13)

8. Sub-processors and Downstream Model Providers

Given GateLLM's data-flow characteristics, this section distinguishes two categories of third parties: GateLLM platform sub-processors (engaged by the Processor to operate the service) and downstream model providers (selected and configured by the Controller via BYOK).

8.1 GateLLM Platform Sub-processors

The Controller authorizes the Processor to engage the following sub-processors for the operation of GateLLM account, license, and support services (not involving prompt / completion content):

  • Supabase Inc.: Database storage and authentication services (accounts, licenses)
  • Stripe Inc.: Payment processing services (billing information)
  • Resend Inc.: Email delivery services (notifications and support tickets)
  • Functional Software, Inc. (Sentry): Error monitoring — used to diagnose frontend and backend errors. Frontend Sentry is consent-gated; backend Edge Functions are always enabled. May process error stack traces, browser type, and IP address. Does not process prompt content.
  • Google LLC: Cookie-based analytics (processes online identifiers such as client ID and device/browser data; IP is collected then discarded by Google, never logged); data transferred to the US under the EU-US DPF (SCCs as fallback); retention 2 months. The analytics script loads on every page but runs under Google Consent Mode v2 in a denied state by default — no cookies are set and no persistent client ID is generated, only an anonymized ping without identifiers is sent; full measurement and analytics cookies activate only after the user accepts analytics.

The Processor will ensure that all platform sub-processors are bound by written agreements providing the same level of data protection as this DPA. The complete and up-to-date list is available on the /subprocessors page.

Sub-processor List

8.2 Downstream Model Providers (BYOK, selected by the Controller)

GateLLM connects to 100+ downstream model providers via BYOK (bring-your-own-key). The Controller uses its own API keys, configured in its own GateLLM instance; requests go straight from the gateway process within the Controller's infrastructure to the provider's official API. The Processor does not relay or store the keys (keys live in gateway memory only, never persisted).

Key legal status: Downstream model providers are selected and directly engaged by the Controller. When the Controller forwards a prompt containing personal data to a provider, the legal relationship between that provider and the Controller (whether it constitutes an independent controller, joint controller, or processor) is determined by the provider's data processing terms and applicable law. The Controller is responsible for separately assessing and executing any necessary agreements (such as the provider's own DPA). The Processor does not assume liability for the data-processing practices of downstream model providers, but commits to disclosing each provider's public data-use categorization on the /subprocessors page to assist the Controller in this assessment.

The data-use categorization of each downstream model provider (whether used for training / whether retained / retention period) is available in the "Downstream Model Provider Data-Use Matrix" on the /subprocessors page. This matrix is compiled from providers' publicly stated policies; the Controller should independently verify before onboarding.

No default onboarding: GateLLM ships with no downstream model provider connections pre-configured. Whether a provider is used, and whether prompts containing personal data are sent to it, is determined solely by the keys the Controller configures — entirely opt-in. The Processor does not make this choice for the Controller.

Downstream Model Provider Data-Use Matrix

8.3 Sub-processor Change Notification Process

The Processor will notify the Controller in advance of any addition, replacement, or removal of GateLLM platform sub-processors and provide a reasonable opportunity to object:

  • Notification channels: via the change log on the /subprocessors page and the contact email registered in the Controller's account.
  • Notification timeline: at least 30 days before a new sub-processor goes live (at least 90 days for changes involving sensitive data transfers).
  • Objection window: the Controller may raise a reasonable objection within 30 days of the notice being published. If the Controller objects and no alternative solution can be reached, the Controller may suspend the affected processing or terminate the affected service with a pro-rata refund.
  • Subscription mechanism: the Controller may subscribe to sub-processor change email notifications via security@gatellm.io to ensure none are missed.

Changes to the downstream model provider list are not decided by the Processor (they are added or removed by the Controller) and are not subject to this notification process; however, the Processor will continuously maintain and update the provider data-use matrix on the /subprocessors page for the Controller's reference.

Sub-processor List (incl. change log)

9. Security Measures and Technical Commitments

The Processor will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including but not limited to:

  • Fully self-hosted deployment: the GateLLM software runs within infrastructure (VPC / on-premises data center) owned or controlled by the Controller; the Processor does not host runtime instances.
  • Prompts never persisted: prompts input by the Controller and completions returned by models are forwarded through the gateway process memory and are not persisted in the Processor's systems. BYOK keys live in gateway process memory only and are never written to persistent storage.
  • Direct-to-provider requests: the gateway process sends requests directly to the downstream model provider APIs configured by the Controller, without passing through any relay server operated by the Processor.
  • Encryption in transit: all external communication uses TLS 1.3; internal inter-service communication uses mTLS.
  • Pseudonymization and encryption of personal data: data at rest (account database) encrypted with AES-256.
  • Ensuring the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
  • Restoring the availability of and access to personal data in a timely manner in the event of a physical or technical incident.
  • Regularly testing, assessing, and evaluating the effectiveness of technical measures.
  • Access control: role-based access control (RBAC), least-privilege principle; SSO (OIDC: Azure AD / Okta / generic, plus SAML 2.0 and SCIM 2.0) integration.
  • Audit logging: all administrative operations and API calls are recorded in audit logs; the log retention policy is determined by the Controller's operations team.

Security whitepaper & architecture · Penetration testing & vulnerability disclosure

10. Data Breaches

If the Processor becomes aware of a security breach involving the Controller's personal data, it will notify the Controller without undue delay and within 72 hours of discovery.

The notification will include:

  • A description of the nature of the breach, including the number and categories of data subjects affected
  • The name and contact details of the data protection officer or contact point
  • The likely consequences of the breach
  • The measures taken or proposed to be taken to mitigate its adverse effects

Given that prompt-related data at GateLLM runtime does not pass through the Processor's systems (see the Important note in Section 4), data breach incidents involving prompts are typically perceived and responded to directly by the Controller within its own infrastructure. The Processor commits to notifying the Controller within the timeframe set out in this section when it becomes aware of security vulnerabilities affecting the GateLLM software itself (e.g., gateway process defects). The complete incident response process is available on the /sla page.

11. International Data Transfers

If the Processor transfers the Controller's personal data to a country outside the European Economic Area (EEA), the UK, or Switzerland, it will ensure an appropriate safeguard is in place via one of the following mechanisms:

  • An adequacy decision by the European Commission for that country
  • Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914)
  • The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs (for transfers under UK GDPR)
  • Safeguards recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC) (for transfers under Swiss FADP)
  • Approved Binding Corporate Rules (BCRs)

The Processor will ensure that platform sub-processors comply with the same data transfer requirements.

Cross-border transfers to downstream model providers: when the Controller forwards prompts to a model provider located outside the EEA / UK / Switzerland, that transfer is initiated and engaged directly by the Controller. The Controller is responsible for ensuring appropriate safeguards are in place for the transfer to that provider (e.g., SCCs / IDTA signed by the provider, or the provider's country having an adequacy decision). The Processor marks the primary data-processing region of each provider on the /subprocessors page to assist the Controller in this assessment.

Sub-processor List (incl. provider regions)

12. Data Subject Rights

The Processor will assist the Controller, to the extent reasonably possible, in fulfilling its obligations to respond to requests from data subjects exercising their rights, including:

  • Right of access
  • Right to rectification
  • Right to erasure (right to be forgotten)
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Rights related to automated decision-making

The Processor will notify the Controller of any data subject requests within 5 business days of receipt.

For personal data contained in prompts: because such data is not held in the Processor's systems (see Section 4), responding to data subject rights requests must be handled by the Controller directly within its own infrastructure and with the downstream model providers. The Processor provides necessary technical cooperation (e.g., exporting audit logs) to assist the Controller.

13. Audits and Inspections

The Controller has the right to conduct audits or inspections of the Processor, after reasonable advance notice, to verify the Processor's compliance with this DPA. Audits should:

  • Be conducted during normal business hours
  • Be reasonably limited in frequency and scope (no more than once per year, unless there is evidence of a material breach)
  • Not interfere with the Processor's normal business operations
  • Comply with confidentiality obligations

The Controller may engage an independent third party to conduct audits. The Processor will make available its existing compliance materials as evidence, including security control documentation, a Software Bill of Materials (SBOM), and vulnerability management records, and will reasonably cooperate with such audits.

Audits of the GateLLM software itself: because runtime instances are deployed within the Controller's infrastructure, the Controller may directly audit its own instances. The Processor provides a Software Bill of Materials (SBOM) and architecture documentation for the Controller's security assessment.

14. Deletion and Return of Data

Upon termination of the service or at the Controller's request, the Processor will:

  • Delete all account- and license-related personal data, unless required to store by law
  • Return a copy of personal data in a structured, commonly used format
  • Delete all existing copies, unless required to retain by law

The Processor will provide written confirmation within 30 days of deletion or return.

Prompt-related data: because this data is not held in the Processor's systems in the first place, no deletion needs to be performed by the Processor upon service termination; the Controller should stop its instances and clear related data within its own infrastructure when terminating the use of GateLLM. The Processor provides uninstallation and data-clearing guidance.

15. Liability

Each party shall bear its liability in accordance with applicable data protection laws.

If a party violates its obligations under this DPA, it shall be liable for damages caused thereby. Liability limitations shall follow the provisions in the Terms of Service, but shall not apply to willful misconduct or gross negligence.

Downstream model provider liability: data protection liability arising from the Controller forwarding prompts (containing personal data) to a downstream model provider is defined by the agreement between the Controller and that provider and applicable law; the Processor does not assume joint and several liability. The Processor's liability is limited to its processing obligations at the account and license level as the provider of the GateLLM software.

16. Term and Termination

This DPA takes effect simultaneously with the Terms of Service and remains in effect after termination of the Terms of Service until the Processor deletes or returns all personal data.

Either party may terminate this DPA if the other party breaches a material term of this DPA.

17. Governing Law

This DPA is governed by the laws of the State of Delaware. Any disputes arising from this DPA shall be resolved in the courts of Delaware.

18. Contact and Execution

For data protection inquiries, contact: privacy@gatellm.io.

By using the GateLLM service, you accept the terms of this DPA. For a formally executed copy, contact support@gatellm.io: we respond within 2 business days with a signable version (PDF / Word), accompanied by the applicable SCC modules, a Technical and Organizational Measures (TOMs) annex, and a snapshot of the sub-processor list; we accept your signature workflow or our template, the executed version prevails, and versions are anchored to this page's "Last updated" date.

Sub-processor list · Security & Compliance · Incident Response & Support

GateLLM is a product of Fluxon LLC, a Delaware limited liability company.